arXiv:2411.09055cs.LGcs.AI2024-11

抗数据投毒的联邦学习框架,提升室内定位精度与效率

SAFELOC: Overcoming Data Poisoning Attacks in Heterogeneous Federated Machine Learning for Indoor Localization

  • 融合神经网络检测数据投毒并实现精准定位
  • 均方误差降低5.9倍,最差情况误差降7.8倍
  • 适合移动设备部署,适用于真实多设备场景

基于机器学习的室内定位对众多新兴应用至关重要,但其性能常受移动设备软硬件差异(即设备异构性)和机器学习数据投毒攻击威胁的影响。传统方法在应对这些不确定性时表现有限。为此,本文提出SAFELOC,一种新型框架,在保障模型轻量的前提下,显著降低定位误差并提升鲁棒性。该框架采用联邦学习(FL)机制,在保护用户数据隐私的同时,支持异构移动设备协作。SAFELOC引入一种融合神经网络架构,实现数据投毒检测与定位一体化;同时设计基于动态显著性图的聚合策略,可根据投毒严重程度自适应调整。实验表明,在多种建筑平面、移动设备及数据投毒攻击场景下,SAFELOC相比当前最优框架,平均定位误差降低5.9倍,最坏情况误差降低7.8倍,模型推理延迟减少2.1倍。

原文摘要 · Abstract (English)

Machine learning (ML) based indoor localization solutions are critical for many emerging applications, yet their efficacy is often compromised by hardware/software variations across mobile devices (i.e., device heterogeneity) and the threat of ML data poisoning attacks. Conventional methods aimed at countering these challenges show limited resilience to the uncertainties created by these phenomena. In response, in this paper, we introduce SAFELOC, a novel framework that not only minimizes localization errors under these challenging conditions but also ensures model compactness for efficient mobile device deployment. Our framework targets a distributed and co-operative learning environment that uses federated learning (FL) to preserve user data privacy and assumes heterogeneous mobile devices carried by users (just like in most real-world scenarios). Within this heterogeneous FL context, SAFELOC introduces a novel fused neural network architecture that performs data poisoning detection and localization, with a low model footprint. Additionally, a dynamic saliency map-based aggregation strategy is designed to adapt based on the severity of the detected data poisoning scenario. Experimental evaluations demonstrate that SAFELOC achieves improvements of up to 5.9x in mean localization error, 7.8x in worst-case localization error, and a 2.1x reduction in model inference latency compared to state-of-the-art indoor localization frameworks, across diverse building floorplans, mobile devices, and ML data poisoning attack scenarios.

联邦学习室内定位数据安全模型压缩

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。